Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Level 1 live now · Level 2 from April 2027

CPCSC & CMMC Readiness: Level 1 and Level 2

The Canadian Program for Cyber Security Certification is now mandatory on select federal defence contracts, and Level 2 brings an external assessor in April 2027. We run both: the done-for-you Level 1 self-assessment against 13 requirements, and full Level 2 readiness against all 98 requirements of ITSP.10.171, including the System Security Plan, evidence, and a mock assessment. If you also supply the US Department of Defense, the same program covers CMMC Level 2. Led by a published security researcher, run from Toronto.

Backed by real assessment work. six published CVEs, 15+ penetration tests, and a SOC 2 Type II run to zero exceptions: the case study.
Book a CPCSC scoping call

No certification, no bid

The CPCSC is Public Services and Procurement Canada's new mandatory cyber security certification for the defence supply chain, Canada's counterpart to the U.S. CMMC. Level 1 became available to suppliers on April 1, 2026, and starts appearing in select contracts this summer. Level 2, which is verified by an external assessor rather than self-attested, follows in April 2027. If your certification is not in place when a solicitation closes, you are out of the running. Requirements also flow down to subcontractors who touch the protected information. If you are still figuring out where you stand, our CPCSC guide walks through the requirements before you scope a paid engagement.

01

Built on ITSP.10.171

CPCSC controls come from ITSP.10.171, the Canadian Centre for Cyber Security's profile of NIST SP 800-171. The Level 1 subset is mapped against CAN/DGSI 104 so the work you do also counts toward broader Canadian baseline controls. Level 2 opens up the full 98 requirements across all 17 families.

02

The level is set by the contract

The sensitivity of the information in a given solicitation decides whether you need Level 1, 2, or 3. You do not choose your level; the contract does. We cover Level 1 and Level 2, and help you confirm early which one your pipeline will trigger so you are ready before the bid lands rather than after.

03

Level 2 is a different kind of work

Level 1 is a judgement call you attest to. Level 2 is an external assessment: an accredited certification body samples your evidence against every applicable objective and interviews the people who run the controls. That means a real assessment boundary, a System Security Plan, a POA&M, and controls that have been operating long enough to leave a trail. Budget 9 to 12 months, not weeks.

04

It is annual, not one-and-done

Level 1 is a self-assessment you re-attest every year through the Canada Buys procurement platform. Level 2 adds an annual affirmation between assessment cycles. We build the evidence and cadence so renewal is routine, not a fire drill.

Level 1 and Level 2, done with you

We deliver readiness at both tiers most suppliers will actually face: Level 1, the self-assessed entry tier, and Level 2, the externally assessed tier that lands in April 2027. Here is what each one covers.

Level 1 · Self-assessment

13 requirements

Annual self-assessment, self-attested through Canada Buys. 71 assessment objectives drawn from 6 of the 17 ITSP.10.171 control families:

  • Access Control
  • Identification & Authentication
  • Media Protection
  • Physical Protection
  • System & Communications Protection
  • System & Information Integrity
Level 2 · Certification body

98 requirements

Assessed by a certification body accredited by the Standards Council of Canada, then affirmed annually. All 17 ITSP.10.171 families, adding the 11 that Level 1 leaves out:

  • Awareness & Training, Audit & Accountability
  • Configuration Management, Maintenance
  • Incident Response, Personnel Security
  • Risk Assessment, Security Assessment
  • Planning, System & Services Acquisition
  • Supply Chain Risk Management
US CMMC · Level 2

110 requirements

For suppliers who sell to the US Department of Defense as well. Assessed by a C3PAO on a three-year cycle, scored and affirmed in SPRS:

  • The 110 requirements of NIST SP 800-171
  • 320 assessment objectives
  • Shared control set with ITSP.10.171
  • One SSP and evidence base mapped to both
  • CMMC Level 1 (FAR 52.204-21) where that is all a contract asks for

CPCSC also defines a Level 3 for the most sensitive contracts, assessed directly by National Defence against roughly 200 requirements. That tier is rare among SMB suppliers. If a solicitation puts you there, we will say so during scoping and bring in the right partner rather than stretch to cover it.

Requirement counts reflect the programs as published by PSPC, the Standards Council of Canada, and the US DoD for 2026 and are confirmed against your specific solicitation during scoping.

When CPCSC actually reaches you

The programme is phasing in rather than landing at once, and which phase catches you depends on what you bid on rather than on your size. The dates below are the published rollout; the requirement that matters is whichever one your next solicitation names.

Phase What changes What to do about it
Phase 1
From April 2026
Level 1 requirements become available, covering the 13 baseline security requirements on a self-assessed basis. Run the Level 1 self-assessment now. It is the cheapest phase to be ready for and the one most suppliers will meet first.
Phase 2
From summer 2026
Level 1 starts appearing as a condition inside live solicitations rather than as guidance. Have the attestation in place before a bid needs it. Readiness after the solicitation drops is readiness that arrives late.
Phase 3
April 2027 to March 2028
Levels 2 and 3 phase in. Level 2 covers 98 requirements drawn from ITSP.10.171 and brings an external assessor rather than a self-assessment. If you handle protected information, start Level 2 gap work well ahead of the window. The gap between 13 and 98 requirements is not closed in a quarter.

The certification decision is not ours to make. CPCSC certification rests with the Government of Canada programme, and Level 2 assessments are performed by an external assessor. We run the readiness work, the self-assessment and the evidence, and we say plainly which parts we cannot sign. The same list is on our internal audit page.

What a readiness engagement covers

A Level 1 engagement runs 2 to 5 weeks depending on how much foundation already exists. Level 2 is a program, not a project: 6 to 12 months from scoping to an assessment-ready state, driven mostly by how much remediation the gap assessment turns up and how long controls need to run before an assessor can sample them. Below is what you walk away with.

StandardITSP.10.171, CAN/DGSI 104, NIST SP 800-171
Output L1Completed self-assessment + evidence
Output L2SSP, POA&M, evidence, mock assessment
GapsPrioritized remediation plan
AttestationFiled via Canada Buys with you
Level 12 to 5 weeks typical
Level 26 to 12 months typical
AssessmentWe sit with you through it
RenewalAnnual cadence built in

Why this team, why now

CPCSC is new, but the underlying work (access control, authentication, evidence discipline) is the AppSec and compliance work we have done for years.

·

Canadian, and built for this program

We are based in Toronto and work to the Canadian standards CPCSC is built on (ITSP.10.171 and CAN/DGSI 104), not a U.S. CMMC playbook bolted onto a Canadian form. We know which control maps to which assessment objective on the Canada Buys attestation. When a supplier sells to both governments, we map the evidence once and use it for CPCSC Level 2 and CMMC Level 2 rather than running two programs.

·

Published CVEs and real audit experience

Our founder is a published security researcher with multiple CVEs, and we have taken startups from zero to a passed SOC 2 Type II audit. The discipline that survives an external auditor is the same discipline that survives a CPCSC certification body, which is exactly what Level 2 asks of you.

·

Honest about what we are

We are a readiness and advisory partner, not a certification body, and the rules keep those roles separate for good reason. We close gaps, author the SSP and POA&M, build evidence, and run a mock assessment against the objectives your assessor will use. For Level 1 we complete the self-assessment with you. For Level 2 we prepare you for an accredited certification body, help you select and schedule one, and sit with you through the assessment. The certificate comes from them, not from us.

How we work

Four phases. Level 1 engagements stop after phase three. Fixed scope, no surprises on the invoice.

01

Scope & gap assessment

We confirm which level your contracts require, define the boundary of the systems that handle protected information, and assess your current state against every applicable ITSP.10.171 requirement and assessment objective. At Level 2 that means all 98 requirements, and the boundary decision is the single biggest lever on your cost. You get a clear gap list ranked by effort and risk.

02

Remediate & document

We help your team close the gaps and produce the evidence each requirement needs: policies, configurations, access reviews, logging, training records, and the supporting documentation behind them. At Level 2 this phase also produces your System Security Plan and the Plan of Action and Milestones for anything still open.

03

Attest (Level 1) or mock assess (Level 2)

For Level 1 we complete and file the self-assessment with you on Canada Buys. For Level 2 we run a mock assessment against the same objectives an accredited certification body will use: we sample your evidence, interview your control owners the way an assessor will, and hand you a findings list while there is still time to fix it.

04

Assessment & maintain

For Level 2 we help you select and schedule an accredited certification body, prepare your team for interviews, and stay in the room through the assessment via our auditor management and advocacy service. Then we set the maintenance cadence: annual affirmation, evidence refresh, and re-assessment planning, so you stay eligible without scrambling.

Works well with

Fixed-scope certification readiness offers

Get CPCSC-ready before the bid closes

Tell us which contracts you are chasing, on either side of the border. We will tell you the level you need and scope the readiness work in one call.

Book a Call

Frequently asked questions

What is the CPCSC?

The Canadian Program for Cyber Security Certification (CPCSC) is a mandatory cyber security certification program for contractors and subcontractors bidding on select Government of Canada defence contracts. It is led by Public Services and Procurement Canada (PSPC), with certification bodies accredited by the Standards Council of Canada and the highest-level assessments conducted by National Defence. It is Canada's counterpart to the U.S. CMMC and is built on the ITSP.10.171 control set, Canada's profile of NIST SP 800-171.

What are the three CPCSC levels?

Level 1 requires an annual self-assessment against 13 security requirements and is self-attested. Level 2 requires an external assessment led by a certification body accredited by the Standards Council of Canada, plus an annual affirmation, against the 98 requirements of ITSP.10.171. Level 3 requires assessments conducted by National Defence plus an annual affirmation, against roughly 200 requirements. The level required is set by the sensitivity of the information in a given contract.

What does the CPCSC Level 1 self-assessment involve?

Level 1 asks suppliers to confirm the implementation status of 13 security requirements drawn from 6 of the 17 ITSP.10.171 control families, totalling 71 assessment objectives. The families cover access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. The self-assessment is completed annually and attested through the Canada Buys procurement platform.

What does CPCSC Level 2 require?

Level 2 covers all 98 security requirements in ITSP.10.171, across all 17 control families, and is verified by an external assessment led by a certification body accredited by the Standards Council of Canada rather than by self-attestation. You need a defined assessment boundary, a System Security Plan that describes how every applicable requirement is met, a Plan of Action and Milestones for anything outstanding, working evidence an assessor can sample, and staff who can explain how each control operates day to day. Certification is followed by an annual affirmation. Level 2 requirements are expected in contracts from April 2027.

Do you support US CMMC Level 2 as well?

Yes. CMMC Level 2 covers the 110 security requirements of NIST SP 800-171, assessed against 320 objectives by a C3PAO on a three-year cycle, with a score and annual affirmation posted in SPRS. Because ITSP.10.171 is Canada's profile of the same NIST standard, we run one readiness program for suppliers who sell to both the Department of National Defence and the US Department of Defense, and produce a single System Security Plan and evidence set mapped to both programs.

When does CPCSC take effect?

Level 1 became available to suppliers on April 1, 2026, and Level 1 requirements begin appearing in select defence contracts in summer 2026. Level 2, which requires an external assessment, follows in April 2027. Because assessor capacity is limited, Level 2 readiness work realistically starts 9 to 12 months before you need the certificate in hand.

Do I need CPCSC if I am only a subcontractor?

Often yes. Certification requirements flow down the supply chain. If you handle the protected information covered by a contract, you can be required to hold the same level as the prime, even if you never contract directly with the government. We help map which of your contracts and data flows will trigger a requirement and at what level.

Can traztech certify us?

No, and you should be cautious of anyone who claims they can. Level 2 certificates are issued only by certification bodies accredited by the Standards Council of Canada, Level 3 is assessed by National Defence, and CMMC Level 2 certificates come from an authorized C3PAO. Readiness and certification have to stay separate. We are the readiness partner: we close your control gaps, author the SSP and POA&M, build the evidence, run a mock assessment against the same objectives your assessor will use, and stay with you through the assessment itself so there are no surprises.

Comparing providers? We wrote the buyer's guide, including where we are the wrong answer: how we compare against the other CPCSC providers in Canada.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

6
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it

Published vulnerability research

Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.

That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.

A SOC 2 Type II built from nothing

Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.

The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.

Recent engagements

For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

Want a few notes on this by email?

Short, practical notes on CPCSC Readiness. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

CPCSC Readiness

Explore CPCSC Readiness →